Which Two ISE Actions Enable WLC Monitor Access?
An administrator must enable helpdesk users to view users' information on wireless LAN controllers in a Cisco ISE environment. The solution must meet these requirements: • Authenticate the helpdesk users against the local ISE database. • Allow the helpdesk users to access the Monitor tab tor the WLC. These configurations were performed: • added a wireless LAN controller • configured user accounts • enabled Device Admin Service in Cisco ISE • configured a TACACS profile • configured a policy set • configured an authentication policy • configured an authorization policy Which two actions must be taken in Cisco ISE? (Choose two.)
Community Votes
75% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests which ISE device-admin elements are still required for WLC Monitor access, and the trap is assuming the AireOS controller consumes TACACS command sets like a Cisco IOS switch, when it actually authorizes by management role.
This 300-715 item covers Cisco ISE device administration for a wireless LAN controller, where helpdesk staff must authenticate against the ISE internal database and reach only the WLC Monitor tab. The page establishes that, with the WLC, user accounts, TACACS profile and policies already in place, the two missing actions are assigning the Monitor role in the TACACS profile (B) and creating the helpdesk identity group (C).
Picking E (TACACS command sets) because device administration normally means command authorization, and picking D because the profile is for a wireless controller; the WLC authorizes by whole-menu role, so command sets are never applied and the role value must be Monitor, not "Wireless".
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is deliberately narrow: helpdesk users authenticate to the local ISE database and reach only the Monitor tab of the WLC. Cisco ISE device administration for AireOS wireless controllers is role-based, so the TACACS profile returned in the authorization result must carry the WLC management role, and for read-only Monitor-tab access that role is Monitor — exactly what option B adds to the already-created TACACS profile. Because the device-admin authorization policy matches on who the user is, the helpdesk accounts must sit in their own identity group (option C) so one rule can match them and hand back that Monitor TACACS profile instead of giving every internal admin the same WLC role. The outstanding work therefore lives in the TACACS profile and in identity management, not in RADIUS-level protocol settings or per-command sets. With the policy set, authentication policy and authorization policy already built, these two additions complete the flow the requirements describe.Why the Other Options Are Wrong
Option A is wrong because authentication profiles in ISE define the allowed authentication protocols for RADIUS flows such as 802.1X; TACACS+ device administration against the internal user store simply rides on the authentication policy that is already configured. Option D misstates the role: the attribute a wireless controller consumes from a TACACS profile is its management role, and read-only access to the Monitor tab requires the Monitor role rather than a "Wireless" role. Option E is the strongest distractor, since TACACS command sets are the normal answer for IOS-style per-command authorization, but AireOS WLCs authorize by role and expose menus, so creating command sets does not grant Monitor-tab access. That leaves B and C as the only two actions that satisfy the stated requirements.Community Comment Notes
The 75-vote majority landed on BC, and Cachaman gave the cleanest reasoning: "There is no Wireless role in the TACACS profile", plus the observation that authorization profiles belong to RADIUS, and pointed readers to Cisco's Device Administration of Cisco WLC using Cisco ISE document. Pages reinforced the same point, noting that "Command sets are not used by WLC" and that the controller's RBAC is tied to entire UI menus rather than individual commands, citing the WLC AAA chapter. A minority (luismg) chose BE, arguing that "Commands are used behind the scenes for the monitoring part", but that conflicts with the role-based authorization model the controller actually uses. The community material therefore supports the role-and-identity-group pair rather than command sets.Official Reference
Exam Strategy
Read the list of configurations already performed and subtract it from the requirements: the two missing actions are by definition the ones not yet on that list. For any WLC device-admin question, remember that the controller consumes a management role from the TACACS profile, which is why command sets are the recurring trap answer.
Frequently Asked Questions
Why must the Monitor role be assigned inside the TACACS profile?
The WLC authorizes by management role, so ISE must return the Monitor role in the TACACS profile to restrict helpdesk users to the Monitor tab.
Why isn't a TACACS command set needed for the Cisco WLC?
AireOS controllers use role-based access control over whole UI menus rather than per-command authorization, so command sets (E) have no effect.